Suspicious domain name determination method, device, equipment, storage medium and product
By obtaining the domain name resolution records from the client IPs of the target industry and using preset filtering rules to exclude domains with lower suspicion, the problem of filtering out APT attack domains from a massive number of domains is solved. This enables the rapid filtering of suspicious domains for further detection and improves the efficiency of security protection.
Patent Information
- Application Number
- CN202610787106.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-02
- Publication Date
- 2026-08-25
AI Technical Summary
Existing technologies struggle to filter out domains suspected of being used in APT attacks from a massive number of domains, making it more difficult to prevent APT attacks.
By obtaining the domain name resolution records of the target industry's client IPs, statistics and filtering are performed. Pre-set filtering rules are used to exclude domains with low suspicion and identify suspicious domains, including filtering based on features such as the number of subdomains, traffic ranking, domain registration information and domain traffic.
Quickly filtering out suspicious domains reduces the difficulty of discovering domains used in APT attacks and improves the efficiency of security protection.
Smart Images

Figure CN122640195A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to methods, apparatus, devices, storage media and products for identifying suspicious domain names. Background Technology
[0002] Advanced Persistent Threats (APTs) refer to long-term, covert cyber intrusion activities carried out by organized attackers against high-value targets. APT attacks typically use specific domains. Identifying the domains used in such attacks is crucial for prevention. However, given the sheer volume of domain names on the internet, current technologies struggle to sift through this vast pool to identify domains suspected of being used by APT attacks. Summary of the Invention
[0003] The main purpose of this application is to provide a method, apparatus, device, storage medium and product for identifying suspicious domain names, in order to solve the technical problem that it is difficult for related technologies to filter out domain names suspected of being used by APT attacks from a massive number of domain names.
[0004] To achieve the above objectives, this application proposes a method for identifying suspicious domain names, the method comprising: Obtain the domain name resolution records to be analyzed based on the client IPs of the target industry; The domain name resolution records are statistically analyzed to determine the domain name to be tested; The domain names to be detected are filtered according to preset filtering rules to identify suspicious domain names.
[0005] Optionally, the preset filtering rules are set according to the number of subdomains; The step of filtering the domain names to be detected according to preset filtering rules to determine suspicious domain names includes: Obtain the main domain name corresponding to each domain name to be tested; The number of subdomains corresponding to each main domain is determined based on the domain name to be detected; Domains whose subdomains are less than a preset threshold are identified as suspicious domains.
[0006] Optionally, the preset filtering rules are set according to the ranking of access volume; The step of filtering the domain names to be detected according to preset filtering rules to determine suspicious domain names includes: Obtain the domain access volume corresponding to each domain to be tested; The domains to be tested are sorted from highest to lowest based on their respective domain access volume, and a sorting result is generated. Domains ranked after the Nth in the sorting results are considered suspicious domains.
[0007] Optionally, the preset filtering rules are set based on the domain name registration information; The step of filtering the domain names to be detected according to preset filtering rules to determine suspicious domain names includes: Obtain the domain registration information corresponding to each domain to be detected. The domain registration information includes at least one of the following: registration duration, domain filing record, domain registration vendor, and IP address pointed to by the domain. Domains that have been registered for less than a preset duration threshold, have no domain name filing record, are registered with a domain name registered by ...
[0008] Optionally, the preset filtering rules are set based on the domain name access volume; The step of filtering the domain names to be detected according to preset filtering rules to determine suspicious domain names includes: Obtain the page views and / or unique visitors for each domain to be tested; Domains whose page views are less than a preset page view threshold and / or whose unique visitors are less than a preset unique visit threshold are identified as suspicious domains.
[0009] Optionally, obtaining the domain name resolution records to be analyzed based on the client IP of the target industry includes: Obtain the daily log volume of each client IP in the target industry within a preset time period; If the daily log volume is less than the preset log volume threshold within the preset time period, the client IP is selected as the target client IP. Obtain the domain name resolution records to be analyzed based on the target client IP.
[0010] Optionally, the step of statistically analyzing the domain name resolution records to determine the domain name to be detected includes: The domain name resolution records are grouped based on the domain names contained in the records to obtain multiple subsets of domain name resolution records; Perform IP unit statistics on each subset of domain name resolution records to obtain the number of IP units corresponding to each subset of domain name resolution records; Domains corresponding to a subset of domain name resolution records whose IP address count is greater than or equal to a preset threshold number are selected as the domains to be tested.
[0011] Optionally, the step of performing IP unit statistics on each subset of domain name resolution records to obtain the number of IP units corresponding to each subset of domain name resolution records includes: Retrieve the C-segment data corresponding to each client IP in each subset of domain name resolution records; The C segment data is deduplicated to obtain the number of IP units corresponding to each subset of domain name resolution records.
[0012] Optionally, before selecting the domain names corresponding to the subset of domain name resolution records whose corresponding IP unit count is greater than or equal to a preset unit count threshold as the domain names to be detected, the method further includes: Obtain the total number of IP units in the target industry; The preset unit number threshold is determined based on the total number of IP units and the preset judgment ratio.
[0013] Optionally, before selecting the domain names corresponding to the subset of domain name resolution records whose corresponding IP unit count is greater than or equal to a preset unit count threshold as the domain names to be detected, the method further includes: Obtain the total number of IP units in the target industry; The total number of IP units is matched with each preset total range to determine the target range; The determination threshold corresponding to the target interval is used as the preset unit number threshold.
[0014] Optionally, after filtering the domain name to be detected according to preset filtering rules and determining the suspicious domain name, the method further includes: Obtain domain-related information and domain AI scores for each suspicious domain; A list of suspicious domains is constructed based on the domain-related information and the domain AI score.
[0015] Furthermore, to achieve the above objectives, this application also proposes a suspicious domain name determination device, which includes: The acquisition module is used to obtain the domain name resolution records to be analyzed based on the client IP of the target industry; The statistics module is used to perform statistics on the domain name resolution records to determine the domain name to be tested; The filtering module is used to filter the domain name to be detected according to preset filtering rules to identify suspicious domain names.
[0016] Optionally, the preset filtering rules are set according to the number of subdomains; The filtering module is also used to obtain the main domain corresponding to each domain to be detected; determine the number of subdomains corresponding to each main domain based on the domain to be detected; and identify the domain to be detected corresponding to the main domain whose number of subdomains is less than a preset threshold as a suspicious domain.
[0017] Optionally, the preset filtering rules are set according to the ranking of access volume; The filtering module is also used to obtain the domain access volume corresponding to each domain to be detected; sort each domain to be detected from high to low based on the corresponding domain access volume, and generate a sorting result; and take the domain to be detected after the Nth position in the sorting result as a suspicious domain.
[0018] Optionally, the preset filtering rules are set based on the domain name registration information; The filtering module is also used to obtain the domain registration information corresponding to each domain name to be detected. The domain registration information includes at least one of the following: registration duration, domain name filing record, domain name registration manufacturer, and domain name pointing IP. Domain names to be detected that have a registration duration of less than a preset duration threshold, no domain name filing record, domain name registration manufacturer not located in a preset region, and / or domain name pointing IP not located in a preset region are designated as suspicious domain names.
[0019] Optionally, the preset filtering rules are set based on the domain name access volume; The filtering module is also used to obtain the page views and / or unique visitors corresponding to each domain name to be detected; and to designate domain names to be detected whose corresponding page views are less than a preset page view threshold and / or whose corresponding unique visitors are less than a preset visitor threshold as suspicious domain names.
[0020] Optionally, the acquisition module is further configured to: acquire the daily log volume of each client IP within a preset time period based on the client IP of the target industry; if the daily log volume within the preset time period is less than a preset log volume threshold, the client IP is selected as the target client IP; and acquire the domain name resolution records to be analyzed based on the target client IP.
[0021] In addition, to achieve the above objectives, this application also proposes a suspicious domain name determination device, the device comprising: a memory, a processor, and a computer program stored on the memory and executable on the processor, the computer program being configured to implement the steps of the suspicious domain name determination method as described above.
[0022] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and which, when executed by a processor, implements the steps of the suspicious domain name determination method described above.
[0023] In addition, to achieve the above objectives, this application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the suspicious domain name determination method described above.
[0024] One or more technical solutions proposed in this application have at least the following technical effects: By statistically analyzing the DNS resolution records of the domains to be analyzed, the domains to be detected that need further analysis are identified. Then, based on the preset filtering rules built on the characteristics of the domains used by APT attackers, the domains to be detected are filtered to exclude domains with low suspicion and identify suspicious domains. This can quickly screen a large number of domains and identify the suspicious ones, so that relevant security personnel can conduct further detection. This reduces the difficulty of discovering the domains used by APT attacks and facilitates security protection. Attached Figure Description
[0025] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0026] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0027] Figure 1 This is a flowchart illustrating an embodiment of the method for determining suspicious domain names in this application. Figure 2 This is a flowchart illustrating Embodiment 2 of the method for determining suspicious domain names in this application. Figure 3 This is a flowchart illustrating Embodiment 3 of the method for determining suspicious domain names in this application; Figure 4 This is a schematic diagram of the module structure of the suspicious domain name determination device according to an embodiment of this application; Figure 5 This is a schematic diagram of the device structure of the hardware operating environment involved in the suspicious domain name determination method in this application embodiment.
[0028] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0029] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.
[0030] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.
[0031] Based on this, the embodiments of this application provide a method for determining suspicious domain names, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the method for determining suspicious domain names in this application.
[0032] In this embodiment, the method for determining suspicious domain names includes steps S10 to S30: Step S10: Obtain the domain name resolution records to be analyzed based on the client IP of the target industry.
[0033] It should be noted that the execution subject of this embodiment can be the suspicious domain name determination device. The suspicious domain name determination device can be a personal computer, a server or other electronic device, or other devices that can achieve the same or similar functions. This embodiment does not limit this. In this embodiment and the following embodiments, the suspicious domain name determination device is used as an example to illustrate the suspicious domain name determination method of this application.
[0034] It should be noted that the target industry can be any industry suspected of being attacked by an APT. The target industry can be pre-specified by the administrators of the devices identified by the suspicious domain, for example, the semiconductor industry. The domain name resolution records to be analyzed can be the portion of historical domain name resolution records (which can be simply referred to as PDNS record data) collected through Passive DNS (PDNS) technology that is related to the client's IP address.
[0035] DNS (Domain Name System) is the core infrastructure of the Internet, used to resolve domain names into IP addresses. PDNS (Passive DNS) is a system that passively collects, stores, and analyzes DNS resolution data to build historical domain name resolution records. It forms a database of "domain name-IP address" mapping relationships by listening to and recording real DNS traffic in the network (such as response data from recursive servers, authoritative servers, or network egress).
[0036] In practical use, administrators of devices that identify suspicious domain names can obtain client IPs by statistically analyzing the IP (Internet Protocol) addresses used by various companies in the target industry, and then look up the domain name resolution records corresponding to the client IPs on the DNS server.
[0037] The domain name resolution record corresponding to the client IP can be the record data constructed by the DNS server based on PDNS technology when the client IP sends a DNS resolution request to the DNS server. However, to ensure comprehensive data acquisition, when retrieving the domain name resolution record corresponding to the client IP, it is possible to access public DNS servers, or even authoritative DNS servers; this embodiment does not impose any restrictions on this.
[0038] Step S20: Statistically analyze the domain name resolution records to determine the domain name to be tested.
[0039] In practical use, after obtaining the domain name resolution records, the domain name resolution records can be statistically analyzed, and some domain names that are obviously not APT attacks can be filtered out based on the statistical results, thereby obtaining the domain name to be detected.
[0040] For example, APT attacks generally do not target only one company. If a domain name is accessed by only one company's IP address, then the domain name is unlikely to be used by an APT attack, and in this case, the domain name can be excluded from the list of domain names to be detected.
[0041] Understandably, statistical filtering can significantly reduce the number of domains that need further analysis, thereby improving the efficiency of the analysis.
[0042] Step S30: Filter the domain names to be detected according to preset filtering rules to determine suspicious domain names. In practical use, after identifying the domain name to be detected, it can be filtered based on preset filtering rules to remove those that clearly do not match the characteristics of domain names used in APT attacks, thereby obtaining suspicious domain names. These preset filtering rules can be set based on the characteristics of the domain names used in APT attack activities.
[0043] In a specific implementation, the preset filtering rules can be set based on the number of subdomains. In this case, step S30 in this embodiment may include: Obtain the main domain name corresponding to each domain name to be tested; The number of subdomains corresponding to each main domain is determined based on the domain name to be detected; Domains whose subdomains are less than a preset threshold are identified as suspicious domains.
[0044] In practical use, you can first obtain the main domain corresponding to each domain to be tested. The main domain can be a second-level domain (SLD). For example, if the domain to be tested is "A.KK.com", its root domain is ".com" and its second-level domain is "KK.com", then its main domain is "KK.com".
[0045] Next, the domains to be tested can be counted to determine the number of subdomains corresponding to each main domain. For example, for the main domain "KK.com", if there are "A.KK.com", "B.KK.com" and "C.KK.com" among the domains to be tested, then the number of subdomains corresponding to this main domain is 3.
[0046] It should be noted that since the domains used in APT attacks provide relatively few functions, they usually do not use too many subdomains. If a main domain has a small number of subdomains, it is likely that it is a domain used in an APT attack. Therefore, the domains to be detected corresponding to main domains with fewer than a preset threshold of subdomains can be considered as suspicious domains.
[0047] The preset threshold for the number of suspicious domains can be pre-set by the administrator of the device identifying the suspicious domains, for example, setting the preset threshold to 5. The domain to be detected corresponding to the main domain can be a domain belonging to that main domain, for example, the domain to be detected is the main domain itself, or the main domain corresponding to the domain to be detected is that main domain.
[0048] Understandably, companies typically set up a certain number of subdomains when registering a domain name to break down the functions or services it provides. Therefore, filtering can be performed based on the number of subdomains corresponding to the main domain name to remove some domains that are clearly inconsistent with the characteristics of domains used in non-APT attacks.
[0049] In a specific implementation, the preset filtering rules can be set based on the ranking of access volume. In this case, step S30 in this embodiment may include: Obtain the domain access volume corresponding to each domain to be tested; The domains to be tested are sorted from highest to lowest based on their respective domain access volume, and a sorting result is generated. Domains ranked after the Nth in the sorting results are considered suspicious domains.
[0050] It should be noted that APT attacks are generally targeted and are usually only used when launching an attack. As a result, the domains used in APT attacks typically have very low traffic. Therefore, the domains to be detected can be sorted from high to low traffic to generate a ranking result. Then, the top N domains are filtered out, and the domains after the Nth in the ranking result are considered suspicious domains.
[0051] In practical use, the domain traffic volume corresponding to the domain to be detected can be obtained from traffic statistics platforms, operators, etc., and this embodiment does not impose any restrictions on this. N can be preset by the administrator of the suspicious domain identification device based on the estimated volume of the domain to be detected. For example, if the administrator of the suspicious domain identification device estimates that the volume of the domain to be detected is in the tens of millions, then the top 10% of the traffic volume can be removed, and N can be set to 1 million, with the portion after 1 million being regarded as suspicious domains.
[0052] The examples provided here are for illustrative purposes only and do not limit the specific values. The percentage to be removed can be adjusted according to actual needs, and this embodiment does not impose any restrictions on it.
[0053] In practical applications, the domain access volume corresponding to the domain to be tested can be obtained by querying the domain to be tested directly. Depending on the actual needs, the access volume of the domain to be tested can also be added to the access volume of the subdomains of the domain to be tested and used as the access volume for ranking. This embodiment does not limit this.
[0054] In a specific implementation, the preset filtering rules can be set based on domain registration information. In this case, step S30 in this embodiment may include: Obtain the domain registration information corresponding to each domain to be detected. The domain registration information includes at least one of the following: registration duration, domain filing record, domain registration vendor, and IP address pointed to by the domain. Domains that have been registered for less than a preset duration threshold, have no domain name filing record, are registered with a domain name registered by ...
[0055] It should be noted that the preset zone can be an area under APT attack, and can be determined by suspicious domain names to be pre-configured on the device. Domains used by APT attackers may also have at least one of the following characteristics: The domain names used are generally relatively new and have a relatively short lifespan. They are usually newly registered domain names, and the same domain name is rarely used for more than 3-5 years. To avoid being used for evidence collection, attackers typically avoid using the network infrastructure of the attacked region. For example, attackers usually do not register domain names with domain name registrars in the attacked region, and attackers usually do not use VPS in the attacked region. Domain name registration is generally not possible.
[0056] Based on the above characteristics, the domain registration information corresponding to each domain to be detected can be obtained. The domain registration information may include at least one of the following: registration duration, domain filing record, domain registration vendor, and the IP address to which the domain points.
[0057] In practical use, if the registered duration of the domain name to be detected is less than the preset duration threshold, it means that the domain name has been used for a short time and may be a domain name used by APT attackers. Therefore, it can be regarded as a suspicious domain name. If the domain name to be tested does not have a domain name registration record, it means that the domain name has not been legally registered and may be a domain name used by APT attackers. Therefore, it can be regarded as a suspicious domain name. If the domain name to be tested is registered by a company outside the preset region, it means that the domain name was not registered by a company in the attacked region and may be a domain name used by APT attackers. Therefore, it can be regarded as a suspicious domain name. If the domain name to be tested points to an IP address outside the preset zone, it means that the domain name was not registered in the attacked zone and may be a domain name used by APT attackers. Therefore, it can be considered a suspicious domain name.
[0058] In some cases, domain name registration or filing is only performed on the main domain. Therefore, we can first obtain the main domain corresponding to the domain to be tested, and then make subsequent judgments based on the domain registration information of the main domain. This embodiment does not impose any restrictions on this.
[0059] In a specific implementation, the preset filtering rules can be set based on the number of domain visits. In this case, step S30 in this embodiment may include: Obtain the page views and / or unique visitors for each domain to be tested; Domains whose page views are less than a preset page view threshold and / or whose unique visitors are less than a preset unique visit threshold are identified as suspicious domains.
[0060] In practical use, the page views and / or unique visitors corresponding to the domain name to be tested can be obtained through third-party tools or platforms. For example, the page views and / or unique visitors corresponding to the domain name to be tested can be obtained by accessing the operator's platform.
[0061] It should be noted that the domains used by APT attackers are generally only used for attacks and have relatively low traffic. In order to reduce the probability of being detected, APT attackers generally do not have many visitors to the domain. Therefore, if the corresponding page views are greater than the preset visit threshold and / or the corresponding unique visitors are greater than or equal to the preset visit threshold, it can be determined that the domain to be tested is not suspected of being an APT attack and can be excluded from the list of suspicious domains. Conversely, if the corresponding page views are less than the preset page view threshold, and / or the corresponding unique visitors are less than the preset unique visitors threshold, it indicates that the domain to be tested has low page views and / or low visitor count, and is suspected of being an APT attack. The domain to be tested can be identified as a suspicious domain.
[0062] The preset access threshold and the preset visitor threshold can both be preset by the administrator of the suspicious domain identification device. For example, the preset access threshold can be set to 100,000 and the preset visitor threshold can be set to 5,000.
[0063] Furthermore, since APT attackers generally do not attack too many targets simultaneously on the same day, judgments can also be made based on the number of unique visitors per day. For example, domains to be tested with a number of unique visitors per day that is less than the threshold for the number of visitors per day can be considered suspicious domains.
[0064] The daily visitor threshold can be preset by the administrator of the suspicious domain identification device, for example, setting the daily visitor threshold to 200.
[0065] In practical applications, the three types of detection—page views, unique visitors, and daily unique visitors—can be performed independently or in combination. This embodiment does not impose any restrictions on this.
[0066] In a specific implementation, to facilitate further testing by relevant testing personnel, step S30 of this embodiment may further include: Obtain domain-related information and domain AI scores for each suspicious domain; A list of suspicious domains is constructed based on the domain-related information and the domain AI score.
[0067] It should be noted that domain name-related information may include the domain's WHOIS registration information, the IP reputation of the IP address the domain points to (rdataIP), the IP region it belongs to, the Autonomous System Number (ASN), the number of client IPs accessing the domain, and the proportion of client IPs located in key cities, etc. Domain AI scoring can be a rating value generated by using a large model to comprehensively score and evaluate the potential commercial value and brand potential of a domain name.
[0068] In practical use, the domain information and AI scores corresponding to each suspicious domain can be aggregated into a detailed list of suspicious domains, making it convenient for relevant testing personnel to view and quickly conduct further testing. If necessary, PDNS record data related to the suspicious domains within a certain time period can also be obtained and provided to the relevant testing personnel along with the detailed list of suspicious domains.
[0069] It should be noted that the preset filtering rules described in this embodiment can be used individually or in combination, for example: During filtering, the domain to be tested is filtered using any one of the preset filtering rules set based on the number of subdomains, the ranking of visits, the domain registration information, or the domain visits. Of course, you can also filter the domain to be tested based on at least two of the preset filtering rules set by the number of subdomains, the ranking of visits, the domain registration information, and the domain visits. For example, if the preset filtering rules are set based on two factors, such as the number of subdomains and the ranking of visits, then during filtering, you can first perform the first filtering based on one of the factors, and then perform the second filtering based on the other factor.
[0070] Of course, multiple preset filtering rules can be set, and filtering can be performed sequentially based on these rules. For example, preset filtering rules can be set based on the number of subdomains and the ranking of visits, respectively. Then, the preset filtering rule set based on the number of subdomains can be used for the first filtering, and the preset filtering rule set based on the ranking of visits can be used for the second filtering. This embodiment does not limit this.
[0071] This embodiment provides a method for identifying suspicious domain names. By statistically analyzing the DNS records of the domain names to be analyzed, the domain names to be detected that require further analysis are identified. Then, based on preset filtering rules constructed according to the characteristics of domain names used by APT attackers, the domain names to be detected are filtered to exclude domain names with low suspicion and identify suspicious domain names. This method can quickly screen a large number of domain names and identify the suspicious ones, so that relevant security personnel can conduct further detection. It reduces the difficulty of discovering the domain names used by APT attacks and facilitates security protection.
[0072] Based on the first embodiment of this application, in the second embodiment of this application, the content that is the same as or similar to that in Embodiment 1 above can be referred to the above description, and will not be repeated hereafter. Based on this, please refer to... Figure 2 Step S20 includes steps S201 to S203: Step S201: Group the domain name resolution records based on the domain names contained in the records to obtain multiple subsets of domain name resolution records.
[0073] It should be noted that each time a domain name resolution is performed, there is actually a domain name that is to be resolved, and the domain name resolution record will record the domain name. Based on this, the domain name resolution record can be grouped according to the domain name contained in the domain name resolution record, thereby obtaining multiple subsets of domain name resolution records. At this time, each subset of domain name resolution records corresponds to a domain name.
[0074] Step S202: Perform IP unit statistics on each subset of domain name resolution records to obtain the number of IP units corresponding to each subset of domain name resolution records.
[0075] In practical use, IP unit statistics can be performed on each subset of domain name resolution records to obtain the number of IP units corresponding to each subset of domain name resolution records.
[0076] Among them, IP units are used to represent different IP segments.
[0077] In a specific implementation, IP units can be distinguished by the different C-segment data. Step S202 in this embodiment may include: Retrieve the C-segment data corresponding to each client IP in each subset of domain name resolution records; The C segment data is deduplicated to obtain the number of IP units corresponding to each subset of domain name resolution records.
[0078] It should be noted that the C-segment data of the client IP can be a set of C-segment addresses of the client IP, used to represent the network segment to which the client IP belongs. For example, if the client IP is "10.0.1.5", then its corresponding C-segment data is "10.0.1", and the network segment to which the IP belongs is "10.0.1.0-10.0.1.255".
[0079] In practical use, the number of IP units corresponding to each client IP in the DNS record subset can be obtained by deduplicating and counting the C-segment data.
[0080] For example, if the C-segment data corresponding to each client IP in the parsed record subset are "10.0.1", "10.0.1", "10.0.1", "20.0.5", and "20.0.5", then after deduplication of the C-segment data, there are two types: "10.0.1" and "20.0.5". In this case, the IP unit count can be set to 2.
[0081] Step S203: Select the domain names corresponding to the subset of domain name resolution records whose corresponding IP unit count is greater than or equal to the preset unit count threshold as the domain names to be detected.
[0082] It should be noted that APT attackers typically target an entire industry. They usually do not attack a single company, but rather they will target multiple companies within the same industry. Based on this, some domains that clearly do not conform to the characteristics of APT attacks can be removed.
[0083] In practical use, APT attacks are highly industry-specific and targeted. The DNS resolution requests for the target domain are scattered across multiple target units rather than concentrated on a single IP unit. Therefore, if the number of IP units corresponding to a subset of DNS records is greater than or equal to a preset threshold, it means that multiple different IP units have accessed the domain corresponding to this subset of DNS records. In this case, the domain corresponding to this subset of DNS records can be considered suspicious and can be used as a domain to be detected.
[0084] If the preset unit number threshold is set to 1, it means that all domain names will be used as domain names to be detected. If the preset unit number threshold is set to other values greater than 1, the larger the preset unit number threshold is, the fewer domain names to be detected will be, but the corresponding detection coverage will decrease. The smaller the preset threshold for the number of units, the more domain names need to be detected, but the detection efficiency will increase accordingly.
[0085] Specifically, the preset unit number threshold can be pre-set by the suspicious domain name determination device according to the actual detection needs, for example, the preset unit number threshold can be set to 2.
[0086] In a specific implementation, the preset unit number threshold can also be set based on the total number of IP units in the target industry. In this case, before step S203 in this embodiment, the following may also be included: Obtain the total number of IP units in the target industry; The preset unit number threshold is determined based on the total number of IP units and the preset judgment ratio.
[0087] It should be noted that the system can perform IP unit statistics on all client IPs in the target industry to obtain the total number of IP units. The preset judgment ratio can be pre-set by the administrator of the suspicious domain identification device.
[0088] For example: Suppose there are 100 companies in the target industry, and each company has a different IP address. In this case, the total number of IP addresses in the target industry is 100. If the preset judgment ratio is set to 2%, then the preset unit threshold is 100 * 2% = 2.
[0089] In a specific implementation, the preset unit number threshold can also be set according to the range of the total number of IP units in the target industry. In this case, before step S203 in this embodiment, the following may also be included: Obtain the total number of IP units in the target industry; The total number of IP units is matched with each preset total range to determine the target range; The determination threshold corresponding to the target interval is used as the preset unit number threshold.
[0090] It should be noted that the preset total range can be set in advance by the administrator of the suspicious domain name identification device, and each preset total range corresponds to a judgment threshold.
[0091] For example: Suppose that the preset total number ranges are 0-100, 101-500, 501-1000, and above 100, and the corresponding judgment thresholds for each preset total number range are 2, 3, 4, and 5, respectively; If the total number of IP units in the target industry is 80, then the corresponding target range is 0-100. In this case, the judgment threshold 2 corresponding to 0-100 can be used as the preset unit number threshold.
[0092] This embodiment provides a method for identifying suspicious domain names. Based on the corresponding IP unit, this embodiment performs a preliminary screening of the statistically obtained domain names, which can significantly reduce the number of domain names that need to be further analyzed and processed, and improve the efficiency of identifying suspicious domain names.
[0093] Based on the first embodiment of this application, in the third embodiment of this application, the content that is the same as or similar to that in the first embodiment described above can be referred to the above description, and will not be repeated hereafter. Based on this, please refer to... Figure 3 Step S10 includes steps S101 to S103: Step S101: Obtain the daily log volume of each client IP in the target industry within a preset time period.
[0094] It should be noted that the preset time period can be pre-set by the administrator of the device identified by the suspicious domain name, for example, setting the preset time period to within 1 year or within 1 month.
[0095] In practical use, you can query the DNS server to obtain the number of PDNS records related to each client IP for a preset time period each day, thereby obtaining the daily log volume.
[0096] Step S102: If the daily log volume is less than the preset log volume threshold within the preset time period, the client IP is selected as the target client IP.
[0097] In practical use, if a client IP has an excessive number of log entries on a certain day, it indicates that the client IP is likely a DNS recursive server, which is the result of multiple client IP requests. The PDNS records associated with this client IP are not suitable as filtering data for suspicious domains. Therefore, such client IPs can be excluded from the target client IP list. If the daily log volume of a client IP is less than the preset log volume threshold within a preset time period, it indicates that the client IP is likely the IP of a regular user client. In this case, it can be used as the target client IP.
[0098] Step S103: Obtain the domain name resolution records to be analyzed based on the target client IP.
[0099] In practical use, after determining the target client IP, you can look up the PDNS record data related to the target client IP in the DNS server and use it as the domain name resolution record to be analyzed.
[0100] Understandably, the original PDNS record data contains a large number of "one-to-many" resolution requests generated by recursive servers. If these requests are not cleared, they will cause the frequency of domain names in subsequent statistics to appear artificially high, which will seriously interfere with the accurate location of APT domain names. Therefore, steps S101-S103 can be performed to identify the IP of such recursive servers and exclude them to avoid the interference they cause.
[0101] This embodiment provides a method for identifying suspicious domain names. This embodiment can identify and exclude the IP of recursive servers to avoid interference and improve the accuracy of identifying suspicious domain names.
[0102] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the method for determining suspicious domain names in this application. Any simple modifications based on this technical concept are within the scope of protection of this application.
[0103] This application also provides a device for identifying suspicious domain names; please refer to [reference needed]. Figure 4 The suspicious domain name determination device includes: Module 10 is used to obtain the domain name resolution records to be analyzed based on the client IP of the target industry; The statistics module 20 is used to perform statistics on the domain name resolution records to determine the domain name to be tested; The filtering module 30 is used to filter the domain name to be detected according to preset filtering rules to identify suspicious domain names.
[0104] The suspicious domain name determination device provided in this application, employing the suspicious domain name determination method in the above embodiments, can solve the technical problem that related technologies struggle to filter out domain names suspected of being used by APT attacks from a massive number of domain names. Compared with the prior art, the beneficial effects of the suspicious domain name determination device provided in this application are the same as those of the suspicious domain name determination method provided in the above embodiments, and other technical features in the suspicious domain name determination device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.
[0105] This application provides a suspicious domain name determination device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, which are executed by the at least one processor to enable the at least one processor to perform the suspicious domain name determination method in Embodiment 1 above.
[0106] The following is for reference. Figure 5The diagram illustrates a structural schematic suitable for implementing a suspicious domain name determination device according to embodiments of this application. The suspicious domain name determination device in embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 5 The device for identifying suspicious domain names shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.
[0107] like Figure 5 As shown, the suspicious domain name determination device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory 1002 or a program loaded from a storage device 1003 into a random access memory 1004. The random access memory 1004 also stores various programs and data required for the operation of the suspicious domain name determination device. The processing unit 1001, the read-only memory 1002, and the random access memory 1004 are interconnected via a bus 1005. An input / output interface 1006 is also connected to the bus. Typically, the following systems can be connected to the input / output interface 1006: input devices 1007 including, for example, a touch screen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. Communication device 1009 allows the suspicious domain name determination device to communicate wirelessly or wiredly with other devices to exchange data. While the figure shows suspicious domain name determination devices with various systems, it should be understood that implementation or possession of all the systems shown is not required. More or fewer systems may be implemented alternatively.
[0108] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from read-only memory 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.
[0109] The suspicious domain name determination device provided in this application, employing the suspicious domain name determination method in the above embodiments, can solve the technical problem that related technologies struggle to filter out domain names suspected of being used by APT attacks from a massive number of domain names. Compared with the prior art, the beneficial effects of the suspicious domain name determination device provided in this application are the same as those of the suspicious domain name determination method provided in the above embodiments, and other technical features of this suspicious domain name determination device are the same as those disclosed in the previous embodiment method, and will not be repeated here.
[0110] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.
[0111] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0112] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to execute the suspicious domain name determination method in the above embodiments.
[0113] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0114] The aforementioned computer-readable storage medium may be included in the suspicious domain name determination device; or it may exist independently and not assembled into the suspicious domain name determination device.
[0115] The aforementioned computer-readable storage medium carries one or more programs. When the aforementioned one or more programs are executed by the suspicious domain name determination device, the suspicious domain name determination device: obtains the domain name resolution records to be analyzed based on the client IP of the target industry; performs statistics on the domain name resolution records to determine the domain name to be detected; and filters the domain name to be detected according to preset filtering rules to determine the suspicious domain name.
[0116] Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof. These programming languages include object-oriented programming languages—such as Python, Java, Smalltalk, and C++—and conventional procedural programming languages—such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0117] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0118] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.
[0119] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the aforementioned method for determining suspicious domain names. This solves the technical problem that related technologies struggle to filter out domain names suspected of being used in APT attacks from a massive number of domain names. Compared with existing technologies, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the suspicious domain name determination method provided in the above embodiments, and will not be elaborated upon here.
[0120] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the suspicious domain name determination method described above.
[0121] The computer program product provided in this application can solve the technical problem that related technologies struggle to filter out domains suspected of being used by APT attacks from a massive number of domains. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the suspicious domain name determination method provided in the above embodiments, and will not be repeated here.
[0122] All user-related data involved in this application (such as user privacy data, user behavior data, etc.) were obtained with the user's permission or consent; that is to say, when this application is used in a specific product or technology, user permission is required to obtain and process the relevant data, and the processing of the relevant data must comply with the relevant laws, regulations and regulatory standards of the relevant countries and regions.
[0123] The above description is only a part of the embodiments of this application and does not limit the scope of protection of this application. All equivalent structural transformations made under the technical concept of this application and using the content of this application specification and drawings, or direct / indirect applications in other related technical fields, are included in the scope of protection of this application.
[0124] This application also discloses A1, a method for determining suspicious domain names, the method comprising: Obtain the domain name resolution records to be analyzed based on the client IPs of the target industry; The domain name resolution records are statistically analyzed to determine the domain name to be tested; The domain names to be detected are filtered according to preset filtering rules to identify suspicious domain names.
[0125] A2. The method for determining suspicious domain names as described in A1, wherein the preset filtering rules are set according to the number of subdomains; The step of filtering the domain names to be detected according to preset filtering rules to determine suspicious domain names includes: Obtain the main domain name corresponding to each domain name to be tested; The number of subdomains corresponding to each main domain is determined based on the domain name to be detected; Domains whose subdomains are less than a preset threshold are identified as suspicious domains.
[0126] A3. The method for determining suspicious domain names as described in A1, wherein the preset filtering rules are set according to the ranking of access volume; The step of filtering the domain names to be detected according to preset filtering rules to determine suspicious domain names includes: Obtain the domain access volume corresponding to each domain to be tested; The domains to be tested are sorted from highest to lowest based on their respective domain access volume, and a sorting result is generated. Domains ranked after the Nth in the sorting results are considered suspicious domains.
[0127] A4. The method for determining suspicious domain names as described in A1, wherein the preset filtering rules are set according to the domain name registration information; The step of filtering the domain names to be detected according to preset filtering rules to determine suspicious domain names includes: Obtain the domain registration information corresponding to each domain to be detected. The domain registration information includes at least one of the following: registration duration, domain filing record, domain registration vendor, and IP address pointed to by the domain. Domains that have been registered for less than a preset duration threshold, have no domain name filing record, are registered with a domain name registered by ...
[0128] A5. The method for determining suspicious domain names as described in A1, wherein the preset filtering rules are set according to the domain name access volume; The step of filtering the domain names to be detected according to preset filtering rules to determine suspicious domain names includes: Obtain the page views and / or unique visitors for each domain to be tested; Domains whose page views are less than a preset page view threshold and / or whose unique visitors are less than a preset unique visit threshold are identified as suspicious domains.
[0129] A6. The method for determining suspicious domain names as described in A1, wherein obtaining the domain name resolution records to be analyzed based on the client IP of the target industry includes: Obtain the daily log volume of each client IP in the target industry within a preset time period; If the daily log volume is less than the preset log volume threshold within the preset time period, the client IP is selected as the target client IP. Obtain the domain name resolution records to be analyzed based on the target client IP.
[0130] A7. The method for determining suspicious domain names as described in A1, wherein the step of statistically analyzing the domain name resolution records to determine the domain name to be detected includes: The domain name resolution records are grouped based on the domain names contained in the records to obtain multiple subsets of domain name resolution records; Perform IP unit statistics on each subset of domain name resolution records to obtain the number of IP units corresponding to each subset of domain name resolution records; Domains corresponding to a subset of domain name resolution records whose IP address count is greater than or equal to a preset threshold number are selected as the domains to be tested.
[0131] A8. The method for determining suspicious domain names as described in A7, wherein performing IP unit statistics on each subset of domain name resolution records to obtain the number of IP units corresponding to each subset of domain name resolution records includes: Retrieve the C-segment data corresponding to each client IP in each subset of domain name resolution records; The C segment data is deduplicated to obtain the number of IP units corresponding to each subset of domain name resolution records.
[0132] A9. The method for determining suspicious domain names as described in A7, before selecting the domain names corresponding to the subset of domain name resolution records whose corresponding IP unit number is greater than or equal to a preset unit number threshold as the domain names to be detected, further includes: Obtain the total number of IP units in the target industry; The preset unit number threshold is determined based on the total number of IP units and the preset judgment ratio.
[0133] A10. The method for determining suspicious domain names as described in A7, before selecting the domain names corresponding to the subset of domain name resolution records whose corresponding IP unit number is greater than or equal to a preset unit number threshold as the domain names to be detected, further includes: Obtain the total number of IP units in the target industry; The total number of IP units is matched with each preset total range to determine the target range; The determination threshold corresponding to the target interval is used as the preset unit number threshold.
[0134] A11. The method for determining suspicious domain names as described in any one of A1-A10, after filtering the domain names to be detected according to preset filtering rules to determine suspicious domain names, further includes: Obtain domain-related information and domain AI scores for each suspicious domain; A list of suspicious domains is constructed based on the domain-related information and the domain AI score.
[0135] This application also discloses B12, a suspicious domain name determination device, the suspicious domain name determination device comprising: The acquisition module is used to obtain the domain name resolution records to be analyzed based on the client IP of the target industry; The statistics module is used to perform statistics on the domain name resolution records to determine the domain name to be tested; The filtering module is used to filter the domain name to be detected according to preset filtering rules to identify suspicious domain names.
[0136] B13. The suspicious domain name determination device as described in B12, wherein the preset filtering rules are set according to the number of subdomains; The filtering module is also used to obtain the main domain corresponding to each domain to be detected; determine the number of subdomains corresponding to each main domain based on the domain to be detected; and identify the domain to be detected corresponding to the main domain whose number of subdomains is less than a preset threshold as a suspicious domain.
[0137] B14. The suspicious domain name identification device as described in B12, wherein the preset filtering rules are set according to the ranking of access volume; The filtering module is also used to obtain the domain access volume corresponding to each domain to be detected; sort each domain to be detected from high to low based on the corresponding domain access volume, and generate a sorting result; and take the domain to be detected after the Nth position in the sorting result as a suspicious domain.
[0138] B15. The suspicious domain name determination device as described in B12, wherein the preset filtering rules are set according to the domain name registration information; The filtering module is also used to obtain the domain registration information corresponding to each domain name to be detected. The domain registration information includes at least one of the following: registration duration, domain name filing record, domain name registration manufacturer, and domain name pointing IP. Domain names to be detected that have a registration duration of less than a preset duration threshold, no domain name filing record, domain name registration manufacturer not located in a preset region, and / or domain name pointing IP not located in a preset region are designated as suspicious domain names.
[0139] B16. The suspicious domain name identification device as described in B12, wherein the preset filtering rules are set according to the domain name access volume; The filtering module is also used to obtain the page views and / or unique visitors corresponding to each domain name to be detected; and to designate domain names to be detected whose corresponding page views are less than a preset page view threshold and / or whose corresponding unique visitors are less than a preset visitor threshold as suspicious domain names.
[0140] B17. The suspicious domain name determination device as described in B12, wherein the acquisition module is further configured to: acquire the daily log volume of each client IP within a preset time period based on the client IP of the target industry; if the daily log volume within the preset time period is less than a preset log volume threshold, the client IP is selected as the target client IP; and acquire the domain name resolution records to be analyzed based on the target client IP.
[0141] This application also discloses C18, a suspicious domain name determination device, the device comprising: a memory, a processor, and a computer program stored on the memory and executable on the processor, the computer program being configured to implement the steps of the suspicious domain name determination method as described above.
[0142] This application also discloses D19, a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and which, when executed by a processor, implements the steps of the suspicious domain name determination method as described above.
[0143] This application also discloses E20, a computer program product comprising a computer program that, when executed by a processor, implements the steps of the suspicious domain name determination method as described above.
Claims
1. A method for identifying suspicious domain names, characterized in that, The method for determining suspicious domain names includes: Obtain the domain name resolution records to be analyzed based on the client IPs of the target industry; The domain name resolution records are statistically analyzed to determine the domain name to be tested; The domain names to be detected are filtered according to preset filtering rules to identify suspicious domain names.
2. The method for determining suspicious domain names as described in claim 1, characterized in that, The preset filtering rules are set according to the number of subdomains; The step of filtering the domain names to be detected according to preset filtering rules to determine suspicious domain names includes: Obtain the main domain name corresponding to each domain name to be tested; The number of subdomains corresponding to each main domain is determined based on the domain name to be detected; Domains whose subdomains are less than a preset threshold are identified as suspicious domains.
3. The method for determining suspicious domain names as described in claim 1, characterized in that, The preset filtering rules are set according to the ranking of access volume; The step of filtering the domain names to be detected according to preset filtering rules to determine suspicious domain names includes: Obtain the domain access volume corresponding to each domain to be tested; The domains to be tested are sorted from highest to lowest based on their respective domain access volume, and a sorting result is generated. Domains ranked after the Nth in the sorting results are considered suspicious domains.
4. The method for determining suspicious domain names as described in claim 1, characterized in that, The preset filtering rules are set based on the domain registration information; The step of filtering the domain names to be detected according to preset filtering rules to determine suspicious domain names includes: Obtain the domain registration information corresponding to each domain to be detected. The domain registration information includes at least one of the following: registration duration, domain filing record, domain registration vendor, and IP address pointed to by the domain. Domains that have been registered for less than a preset duration threshold, have no domain name filing record, are registered with a domain name registered by ...
5. The method for determining suspicious domain names as described in claim 1, characterized in that, The preset filtering rules are set based on the domain name access volume; The step of filtering the domain names to be detected according to preset filtering rules to determine suspicious domain names includes: Obtain the page views and / or unique visitors for each domain to be tested; Domains whose page views are less than a preset page view threshold and / or whose unique visitors are less than a preset unique visit threshold are identified as suspicious domains.
6. The method for determining suspicious domain names as described in claim 1, characterized in that, The step of obtaining the domain name resolution records to be analyzed based on the client IP of the target industry includes: Obtain the daily log volume of each client IP in the target industry within a preset time period; If the daily log volume is less than the preset log volume threshold within the preset time period, the client IP is selected as the target client IP. Obtain the domain name resolution records to be analyzed based on the target client IP.
7. A device for identifying suspicious domain names, characterized in that, The suspicious domain name determination device includes: The acquisition module is used to obtain the domain name resolution records to be analyzed based on the client IP of the target industry; The statistics module is used to perform statistics on the domain name resolution records to determine the domain name to be tested; The filtering module is used to filter the domain name to be detected according to preset filtering rules to identify suspicious domain names.
8. A device for identifying suspicious domain names, characterized in that, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the suspicious domain name determination method as described in any one of claims 1 to 6.
9. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the suspicious domain name determination method as described in any one of claims 1 to 6.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the suspicious domain name determination method as described in any one of claims 1 to 6.